Vendor Scorecard

The procurement checklist, pre-filled and signed

Most security and procurement teams ask the same 60 questions. We answer all of them in advance, sign the file, and version it on the trust ledger. Use it as-is or import into your own framework.

Overall score

95%

21 of 22 fully met

Frameworks mapped

6

SIG, CAIQ, ISO, SOC 2, NIST, EU AI Act

Average completion

< 1 day

vs industry 4–6 weeks

Last signed

2026-06-25

By CISO + CFO

Answered checklist

AreaQuestionAnswer
SecuritySOC 2 Type II current within 12 months Yes
SecurityISO 27001:2022 certified Yes
SecurityIndependent penetration test in last 12 months Yes
SecurityBug bounty program active Yes
SecurityCustomer-managed encryption keys Partial
SecurityZero-trust architecture documented Yes
PrivacyGDPR data processing addendum available Yes
PrivacySubprocessor list public + 30d notice Yes
PrivacyEU data residency option Yes
PrivacyDPIA template provided Yes
FinancialAudited financial statements Yes
FinancialCash runway > 24 months Yes
FinancialCustomer funds segregated Yes
Operational99.95% uptime SLA with credits Yes
OperationalIncident response < 30 min MTTR Yes
OperationalBackup tested in last 30 days Yes
AI governanceEU AI Act self-assessment published Yes
AI governanceModel cards for each AI feature Yes
AI governanceHuman-in-the-loop on material decisions Yes
ExitFull data export in open formats Yes
ExitExport deliverable within 24 hours Yes
ExitContractual exit assistance period Yes